IBM Support

LI82168: DEVELOPER PORTAL API TEST TOOL SHOULD SEND GRANT_TYPE AND SCOPE IN FORM BODY INSTEAD OF QUERY PARAMETERS

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Developer Portal API test tool should send grant_type and scope
    in form body instead of query parameters.
    
    Steps to reproduce the issue:
    - Publish an API with OAuth2 security definition (Client
    Credentials Grant)
    - Developer subscribes to this API with an application and
    selects an operation and click "Try it". After enter client id /
    secret and select the scope, when the "Get Token" button is
    clicked next, Developer Portal use below URL to call the token
    endpoint:
    https://token_endpoint?grant_type=client_credentials&scope=samp
    lescope
    

Local fix

Problem summary

  • Developer Portal API test tool should send grant_type and scope
    in form body, instead of query parameters.
    
    These steps can be used to illustrate the issue:
    - Publish an API with OAuth2 security definition (Client
    Credentials Grant)
    - Developer subscribes to this API with an application and
    selects an operation and click "Try it". After enter client id /
    secret and select the scope, when the "Get Token" button is
    clicked, Developer Portal use below URL to call the token
    endpoint:
    https://token_endpoint?grant_type=client_credentials&scope=sampl
    escope
    

Problem conclusion

  • Product is updated in 2018.4.1.17, 10.0.3 and 10.0.1.4 to
    address the issue.
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI82168

  • Reported component name

    API CONNECT ENT

  • Reported component ID

    5725Z2201

  • Reported release

    18X

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-05-18

  • Closed date

    2021-08-09

  • Last modified date

    2021-08-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    API CONNECT ENT

  • Fixed component ID

    5725Z2201

Applicable component levels

  • R18X PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"18X","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 September 2021